peter bassill · operator
$ cve CVE-2014-3110 JSON

CVE-2014-3110 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 5.3% (pctl 92)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to inject arbitrary web script or HTML via invalid input.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS5.34% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2014-07-24
Last modified2026-06-17

Affected (2)

VendorProduct
honeywellfalcon xlweb linux controller
honeywellfalcon xlweb xlwebexe

Public exploits

SourceTitleDate
exploit-dbHoneywell XL Web Controller - Cross-Site Scripting2018-05-24

References

→ the Explorer  ·  watch your stack  ·  NVD